Erlang

Otp

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 02.07.2026 16:06:08
  • Zuletzt bearbeitet 24.07.2026 15:18:32

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre...

  • EPSS 0.24%
  • Veröffentlicht 02.07.2026 16:06:04
  • Zuletzt bearbeitet 24.07.2026 15:18:04

Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass. On DTLS server startup, dtls_server_connection:initial_...

  • EPSS 0.26%
  • Veröffentlicht 02.07.2026 16:06:03
  • Zuletzt bearbeitet 24.07.2026 15:18:01

Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd...

  • EPSS 0.34%
  • Veröffentlicht 10.06.2026 14:41:51
  • Zuletzt bearbeitet 24.09.2026 21:17:14

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking wheth...

  • EPSS 0.19%
  • Veröffentlicht 10.06.2026 14:35:49
  • Zuletzt bearbeitet 24.09.2026 21:17:14

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erla...

  • EPSS 0.28%
  • Veröffentlicht 10.06.2026 14:35:49
  • Zuletzt bearbeitet 24.09.2026 21:17:14

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chr...

  • EPSS 0.23%
  • Veröffentlicht 10.06.2026 14:35:45
  • Zuletzt bearbeitet 24.07.2026 15:17:25

Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet,...

  • EPSS 0.35%
  • Veröffentlicht 10.06.2026 14:35:43
  • Zuletzt bearbeitet 08.09.2026 01:17:31

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with the user_pass...

  • EPSS 0.5%
  • Veröffentlicht 10.06.2026 14:35:38
  • Zuletzt bearbeitet 24.09.2026 21:17:14

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_dr...

  • EPSS 0.14%
  • Veröffentlicht 10.06.2026 14:35:36
  • Zuletzt bearbeitet 24.09.2026 21:17:15

Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C func...